Multifactor Authentication for End Users – John Gunn, Token
Token CEO John Gunn explains why making multifactor authentication (MFA) really work for end users that have access to an organization’s most crucial information requires a ring.
Transcript
This is Techstrong tv. Hey guys, thanks to the throw. We're here with John Gunn, who, c e o for token, and we're talking about multifactor authentication, also known as mfa.
We've been waiting on it for a long, long time, and now I think we're complaining about it. John, welcome the show. Thank you very much for having me on, Michael.
It's a pleasure. So what is the current state of mfa? It seems like we're finally using it a lot more after telling people that they needed to use it for, I don't know how, it feels like years and years, but the implementations are somewhat uneven and the experiences are somewhat uneven.
So, you know, where are we and how did we get here and where do we need to go? Well, that is a great question to start with. I could talk for about two hours on that, but I know I don't have two hours.
Uh, so don't worry, I won't. But, uh, you know, passwords were independent 60 years ago and about 20 years ago, M F A came along The second factor, and some people are still in the view of should we give up passwords? I mean, that is so obsolete, but what's happening now is the companies that have the most to lose.
I mean, if you're a hacker, who do you steal from? Whoever's got the most to, to take. So they're targeting the companies that have the most to lose with the most sophisticated attacks, and that's where MFA is failing.
Legacy MFA is failing. If you're protecting your social media account, no one wants to hack that. You add two-factor authentication, you had the, you're covered.
But if you're trying to stand up against a Russian or North Korean backed cyber, very sophisticated tools, you are at a disadvantage if you're using legacy mfa. And that's where the complaining you mentioned is coming from. And it shows up in the headlines every week you see a new headline about a major company, uh, being hit.
So if that's the case, what exactly are the cyber security folks thinking about? Because it does seem like the criminals have figured out how to get around it. So, um, what do we need to do?
You know, as you, as you know, you know, nobody can say that they're, you know, they're hacker proof because given the time and the resources the hackers will get in, it's just how can you make it so hard to get in that it's not worth pursuing? You bring those odds down and that, and what's happening in the field of MFA is current solutions are still based on humans. You know, passwords were easy to crack, and a lot of two factor methods are easy to crack.
And the current, you know, the legacy MFA is getting beaten. And when you look at, you know, there's so many, there's so much data. It seems like every week there's a new report published by somebody and the data on ransomware, you think these people should talk to each other because sometimes the numbers are totally different.
But then you see certain patterns. And one that that's consistent is that humans are the cause of it. You know, when you see the di uh, Verizon data breach incident report year after year, you know, between 16 80% humans contributed to it, which means somebody got fished, somebody got social engineering, there was an adversary in the middle attack.
1 billion market cap. I haven't looked lately, but it was below 500 million. That's a 600 million hit.
You know, Haynes brands, uh, you know, they, they lost a hundred million in revenue because of their ransomware attack. You know, continental automotive, Uber, all of them were very smart and had a strong security posture that used MFA and all of those. The initial entry point was that, that their MFA got defeated.
Their legacy mfa, adult foods is another one. These, you know, these are all public companies have to disclose where you can read it, but the private ones, you don't know for sure, but they, they even disclosed their financial losses because insurance, insurance won't cover it anymore. And that's a whole separate topic.
I'm sure you have somebody on your show talking about how cyber security insurance is becoming increasingly hard to get. A third of people won't be able to renew this year. The rates are going up.
And it's because of this weakness of legacy mfa and it's because of humans. I mean, God love 'em. If they we're humans, we didn't have 'em.
We wouldn't have employees, we wouldn't have customers. They're essential to life, but we be not with AI in the future, who knows? But, uh, but that, that's what the weakness is.
And so what we're doing with, uh, we're labeling next generation MFA and uh, is we're trying to take the human weakness out of it. Somebody's still, human's still involved, but all the ways that they can be attacked, what's fishing with social engineering, we wanna remove those to protect people's company from their employees. I mean, that sounds negative about people, but that's really what it's, you know, they invest tons in training them and trying to get them not to, you know, fall for these, uh, attacks.
But, but they still do it all takes is one out of 10,000 employees and you know, then you got, you lost 10 million, 15 million, a hundred million. So explain that a little more deeply. What do we mean by a modern approach to MFA and keeping people involved and, but making them less, um, dependent on everybody else to kind of do the right things.
So how do we kind of approach this? Yeah, great question. And, uh, I don't wanna turn this into a product pitch cause that, that's not why I'm here.
I'm here to evangelize next generation of fa we happen to have a solution that, but it starts with, uh, a device that only the authorized person can use. You and dongle are a huge step up from sending an s m s over o t p plain text and they can steal it, it gets hacked. You'll be able to a dongle giant leap forward.
But it still depends on a human not leaving it plugged into device, not leaving it on the table, not leaving it desperate. Somebody else can pick it up and use it. So you're almost there.
So the number one thing is only the authorized person can use it. And that requires biometrics, you know, like a fingerprint and, uh, and it has to also eliminate the vulnerabilities of bringing your own devices. And people say, oh wow, I can do a fingerprint on the phone.
Yes you can, but I mean that mobile device is, is just begging for trouble because, you know, a large number of companies, they can't secure those devices because they belong to the employees. You know, tell employees, Hey, we want, we wanna control that device. We wanna monitor everything you're doing on your device on my phone.
We wanna be able to wipe in an inch if we want to everything on it, just my kids and my dog on there. Forget it. So they can't control a device and all these weaknesses people have, they bring with that device.
And, uh, so it's gotta eliminate the, the the vulnerabilities. Uh, bring your own device. Gotta be something that's hard to lose.
You know, people lose dons all the time. Uh, they're the, the leading provider, one of the leading providers of donals for their marketing message is, you need to buy two, why don't need to buy two? Cause you're gonna lose the first one.
Okay. Raises the price a bit, but also underscores the fact that if you lose it, then it's really hard to use it. Uh, if fight oh two compliant, you know, you've been in the industry for longer than I have and we've both seen the rise of Fido and we've both seen finally the adoption, you know, of Fido after, I dunno, long Fido's been around 15 years, but 10 years people have been advocating it.
So that's a big plus in a requirement. And then if you're not about biometric, biometric data has to be protected. It can't be on a central server, it can't even be accessible.
Uh, and then advice that can't be hack or disassembled and then super easy to use. So what we came up with is the token ring. This is a ring that the user wears is an authentication device.
You can see it just lit up there and, uh, cause it, thanks. I'm, I'm trying to authenticate, put it on. So I put it on my finger, it reads my fingerprint.
There's a little fingerprint reader in there. You can, the camera's focusing on it. So it reads my fingerprint and I put it on now.
So only I unless show up my finger, my fingerprint, you can't use this authenticator that's on my finger. So I have three things on my nightstand, my mobile phone, my wallet, and my ring. But am I on the morning?
I leave the house? Eventually that wallet may go away. Uh, but the ring is always there.
So it's always available, it's always usable. Has none of the vulnerabilities of a mobile phone. There's no wifi to this.
There's no way for a hacker to reach it. No cellular communication. It uses nfc.
So I just knocked twice on the table and broadcast N ffc, I helped it over with the reader and then it communicates my username, my password, my credentials. So when you're doing, you know, pki, uh, and you need to communicate those, those credentials, it communicates through nfc. Very small range of broadcast.
No hacker can pick it up certain the inches of your finger, which is probably not gonna happen. Uh, so it's incredibly secure is the biggest fool on the planet. And I was talking to somebody on the phone.
They said, Hey John, tell me your password. Tell me your credentials. I'm like, I don't know.
I just put the hold the hold the ring over the device and it it communicates it. So that's where it takes the human element out of it. And I don't have to worry about waiting for a code.
Oh, it sent it to my email address that accounts in some, it is on this other device. I don't have my phone with me. It, it just didn't come through on the otp let me request it again.
It still didn't come through. Oh, you request that again, maybe their server's not working, I don't know. But this is always with you and always available, super easy to use.
If you take it apart, you destroy it. Uh, the secret or the seed, whatever you wanna call it, is in a secure element. And so are my biometrics.
And they never leave this. So if I'm one of those people who says, Hey, I can change a password, but I can't change my fingerprints never leaving this, there's a growing number of regulations involving biometrics and more to come. This meets all of them.
Biometrics never leave the advice. So we try to put all those things that will make this, this next generation and we'll take the human element out of it, let hackers go find a different way in. So what would happen if I got a copy of your fingerprint somehow and I stole the ring?
Would that work? Or does it have to be like an actual live finger? You have a really tough time doing it because it, it is not a, a visual one, it does it by capacitance.
So you probably need to have my cut my finger off and do it while it was still kind of juicy with, with blood to have to read those ridges. But if you're in the room with me, you can cut my finger off. I have much bigger problems than you getting access to my computer.
Yeah, all, all these attacks happen, you know, not all 'em, virtually all of 'em happen, you know, from Russian or Korea. I ran adversaries and they're not in the room. They're not gonna get that.
So that, that in theory, some may be able to approve that one day, but highly, highly unlikely. All right. So you're saying I got at least six feet from you and I got a headstart, so I'm, I should be okay.
That's good. That, that's a good way of looking at it. You know, to emphasize the point, there was a help net security, one of the publications I read, and they, they had a pretty neat headline, uh, back on April 25th.
It said, uh, that, uh, hackers, uh, attackers are logging in instead of breaking in. That was the headline. Uh, attackers are logging in instead of breaking in.
What they're talking about is they're just logging in as people. And that's what's so difficult. If I hack in moment, I come in that's, you know, zero trust, don't trust anybody cuz people will get in.
But, but they're just logging in as people now. And, uh, if I log in as somebody in finance who can send funds, somebody in HR can access human resources file or any healthcare organization like can access patient records, you know, that, that, that, that that's what we stop, you know, that somebody can do damage the moment they log in. So what do you think the biggest challenge is in trying to get to this next generation of mfa?
Is it a technology challenge or is it really more of a cultural issue at this point? Uh, another great question. It it's really both parts of technology.
We've spent years developing this and it is substantially more expensive, you know, than a regular dongle. If you compare that, you know, to what it's really all charges to send an sms. I mean, for high volume people, I'm sure it's well under a penny, you know, but if you ask somebody, you've lost a hundred million dollars if you could spend, you know, 500,000 and save that hundred billion when you do it, they'd say for sure people who can't get insurance anymore.
And if you've had a breach, you're not, it's, you know, your automobile, you get in a wreck, maybe your rates go up, you get breached, you're not gonna get coverage again. Even if you get coverage, you know, just as with Dole and it's a great company, uh, they acknowledged, you know, our insurance didn't cover all of our losses. They didn't disclose the exact amount, but, uh, the amount of losses there are, you know, are are just beyond that.
You know, you read about extortion and double extortion, triple extortion. I'm sure somebody will coin quadruple extortion and grab some headlines, but it's just, you know, the damage that is done, you know, through all of that. And now increasingly on top of that, after a company, you know, pays to get their data back, pays to have it not disclosed, and people find out, well, I got breached, then they sue.
So it's maybe that is quadruple extortion, you know, when the plaintiff's council comes in and, uh, there are a couple recent cases, one in Texas and one in Alabama where hospitals were hit by ransomware and it compromised their patient care during the attack. And in both these instances, a newborn died, which is just, you know, the most unspeakable tragedy. And uh, you know, it's just, I can't imagine the loss of people are going through, but it's gonna end up in court.
And if you're that hospital, how do you defend, you know? Well, yeah, I could have spent more and protected that. I mean this, the, the amount of the amount of risk that's out there is just huge for organizations.
Mm-hmm. So what would it take for everybody to have a ring or will the ring only be used for, you know, very high classified type of use cases or super sensitive data because of the cost? Or are we gonna get to a point where, you know, we'll, you know, we'll be all walking around with a ring and you know, mine might be a little more fashionable than yours, but, you know, we all got one, You know, right now for the customers and we've, uh, this is an overwhelming, the response that we've had, uh, from Fortune 100 accounts and big business.
I mean, we were at RSA in the, in the startup expo, which is not on the floor. It's, you gotta go way down a hall upstairs or way back. It's this little room.
We had just more than a hundred major companies, senior, senior security people come by asking about it. And we recommended most of 'em. You don't need a ring on every employee's finger.
You spend what your business does, you know, it's usually between about 10 to 20%. You know, if they have a good, you know, PAM solution and other solutions to detect intrusion. This is the kind of thing that every employee needs to have, at least at present.
We don't think it's the people who can do damage instantly. Somebody logs in as your C F O or c E O or anybody in finance, anybody in it, any CIS admins, anybody in hr, those people could do damage immediately. And those are the ones that should have a ring for most employees.
Hey, we, we'd love to sell 'em one, but at this point it probably probably isn't necessary. Uh, you know, but that's one of the things we do when we talk with people about their security posture. You know, we evaluate it and make a recommendation and look, you know, so many larger companies have different IAM solutions, different levels of authentication based on users.
And, uh, so those most sensitive, secure risk users are, are the ones that, that we're setting out to protect. All right, folks, while you heard it here, if you're concerned about security, you should do like the song says and put a ring on it. Hey John, thanks for being on the show.
We Haven't licensed that. I don't think you can say that. Michael, always the pleasure to be on your show.
Thank you so much for your time and your interest. All right, back to you guys in the.